> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/administration/setup-sso-integration-on-prisma-cloud/get-started-with-saml-sso/setup-sso-integration-on-prisma-cloud-for-microsoft-azure-active-directory.md).

# Set up Azure AD SSO on Prisma Cloud

To secure administrator access to Prisma Cloud, go to the Microsoft AAD site to configure single sign-on and then configure Prisma Cloud for SSO.

On Prisma Cloud, you can enable single sign-on (SSO) using Microsoft Azure Active Directory (AAD). To enable SSO, you must first complete the setup on the Microsoft AAD. You can then log in with System Administrator privilege on Prisma Cloud to configure SSO and redirect login requests to the IdP login page so that your Prisma Cloud administrative users can log in using SSO.

After you enable SSO, you must access Prisma Cloud from the Microsoft AAD portal. Prisma Cloud supports IdP initiated SSO, and its SAML endpoint supports the POST method only.

1. Set up Microsoft AAD for SSO by creating an external application for Prisma Cloud and configuring SSO for it.
   1. Before you configure Microsoft AAD, log in to your Prisma Cloud instance and copy the Audience URI (SP Entity ID) from Prisma Cloud, by accessing SSO configuration from the **Settings > Access Control** tab. This will be required for SAML configuration once your application is created.
   2. Log in to Microsoft Azure portal as an Administrator with administrator privileges to create an external application.
   3. Select **All Services** and click **Azure Active Directory**.
   4. Select **Enterprise Applications** then click **+New Application** and **Create your own application**.
   5. Choose **Integrate any other application you don’t find in the gallery (Non-gallery)**.
   6. Give your application a descriptive name and click **Create**.
   7. Select **Single Sign-on** under **Manage**.
   8. For **Single Sign-on Mode**, select **SAML-based Sign-on**.
   9. Edit Basic SAML Configuration and enter previously copied Audience URI into **Identitifier (Entity ID)**.
   10. Depending on the location of your tenant, which is displayed in the login URL, copy and paste the Prisma Cloud console URL into **Reply URL** (Assertion Consumer Service URL) field by replacing ‘app’ with ‘api’, and appending /saml at the end. For example: <https://api2.prismacloud.io/saml> for <https://app2.prismacloud.io/>
   11. Edit the User Attributes & Claims section. User Attributes captures information such as first and last name. Claims are key/value-pairs that relate to the user object, for instance a user’s email address. Verify the following according to your environment. By default, claims should apply to any environment.

       Add a new attribute, give it a name and map it to a source attribute( e.g user.jobtitle). The attribute name will be used to configure Prisma Cloud JIT configuration.

       If the attribute has a namespace configured, the namespace and the name of the attribute should be added to Prisma Cloud JIT configuration.
   12. Download **Certificate (Base64)**. This certificate will be used in Step 4 below to complete configuration.
   13. Copy the Azure AD identifier in Azure SSO configuration for later.
   14. (Optional) Copy the Logout URL in Azure SSO configuration for later use. Users are redirected to this page when their browser sesssion terminates.
   15. Click on **Manage - Properties** and copy the User access URL for later.
   16. **Save**.
2. Assign the users from Azure Active Directory to your newly created application.
   1. Log in to Microsoft Azure portal as an Administrator.
   2. From **Manage**, select **User and groups**.
   3. **+Add User** and select and add your users.
   4. **Assign**.
3. If you would like a subset of users to have Administrative Acess you will need to additionally [Add administrative users](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/administration/setup-sso-integration-on-prisma-cloud/add-prisma-cloud-users.md#id2730a69c-eea8-4e00-a7f1-df3b046615bc) to Prisma Cloud.
4. Configure SSO on Prisma Cloud.
   1. Log in to Prisma Cloud and select **Settings > Access Control > SSO**.
   2. **Enable SSO**.
   3. **Audience URI (SP Entity ID)** is a read-only field in the format: <https://app.prismacloud.io?customer=\\><string> to uniquely identify your tenant. Use this value in Configure SAML section in your IdP settings.
   4. For the **Identity Provider Issuer** field, enter the URL of Azure AD identifier noted in the steps above.
   5. Enter **Identity Provider Logout URL** noted in the steps above. You will be redirected to this URL when Prisma Cloud times out.
   6. Enter your IdP **Certificate** in the standard X.509 format.
   7. Enter **Prisma Cloud Access SAML URL** you copied previously. This is the URL to access the Prisma cloud application.

      When you click this URL, after authentication with your IdP, you are redirected to Prisma Cloud. This link along with the Relay State Parameter is used for all the redirection links embedded in notifications such as email, Slack, SQS, and compliance reports.
   8. Provide the **Relay State Param name** for seamless notification forwarding from third party applications such as Splunk, Slack, SQS etc. to Prisma Cloud. Relay State Param name is a SAML specific parameter name. The relay state parameter or value is specific to your Identity Provider. The default value is userinput:\[RelayState] and you will rarely need to change this value. For example, this value is userinput:\[RelayState] for AAD.
   9. **Important**: Ensure that select users can always authenticate directly and log in to the console, in addition to logging in using SSO. Enable **Allow select users to authenticate directly with Prisma Cloud** for **Direct User Authentication**. This step is crucial to avoid getting locked out of the Prisma Cloud console.

      When you enable SSO, it is very important to select a few users who can also access Prisma Cloud directly using the email and password that is registered locally on Prisma Cloud to ensure that you are not locked out of the Console in the event you have misconfigured SSO and need to modify IdP settings. For accessing data through APIs, you need to authenticate directly to Prisma Cloud.

      1. Select the **Users** who can access Prisma Cloud either using local authentication credentials on Prisma Cloud or using SSO.
   10. Verify access using SSO.

       Administrative users for whom you have enabled SSO, must access Prisma Cloud from the Identity Provider’s portal. For example, if you have integrated Prisma Cloud with Azure AAD, administrative users must log in to Azure AD and then click on the Prisma Cloud app icon to access Prisma Cloud.

       Just in Time (JIT) provisioning, used along with SSO automates the process of creating accounts for users. JIT is disabled by default.

## View Login Failures

In the event users have SSO login issues you can view details of failed logins to further troubleshoot. Select **View last SSO login failures**, to see details of last five login issues or errors for SSO authentication for any users.

\+

* You can have only one SAML configuration for all your cloud accounts, per Prisma Cloud tenant.
* If a user is logged in already using the username/password flow, and the user tries to log in via SAML SSO, the token will get updated with the latest login in the browser’s local storage and replace the existing auth-token.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/administration/setup-sso-integration-on-prisma-cloud/get-started-with-saml-sso/setup-sso-integration-on-prisma-cloud-for-microsoft-azure-active-directory.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
